Azure Microsoft Defender Endpoint: How to Integrate or Stream Logs to Azure Log Analytics Workspace

Arnold Reddy 20 Reputation points
2024-07-30T00:51:02.96+00:00

I'm having trouble finding articles on how to stream/connect logs from Microsoft Defender for Endpoint to a new Log Analytics Workspace in the same tenant. Most solutions I've found show Defender for Cloud, but we're using Microsoft Defender for Endpoint and need to send logs to a Log Analytics Workspace in the same tenant in Part 1, then to another LA workspace in another tenant for Part 2. I think Log Ingestion API could be the solution, but I'm looking for examples or usable tutorials. Can anyone share some information or advice?

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,097 questions
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint Training
Microsoft Defender for Endpoint: A Microsoft unified security platform for preventative protection, postbreach detection, and automated investigation and response. Previously known as Microsoft Defender Advanced Threat Protection.Training: Instruction to develop new skills.
29 questions
0 comments No comments
{count} votes

Accepted answer
  1. Clive Watson 6,111 Reputation points MVP
    2024-07-30T07:28:03.52+00:00

    Slightly old but these articles may help with some ideas: https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/blog-series-limitless-advanced-hunting-with-azure-data-explorer/ba-p/2328705
    https://jeffreyappel.nl/export-microsoft-defender-for-endpoint-security-events-with-the-streaming-api/

    Obviously the data is already in a custom Log Analytics workspace (but you can only access it from the portal which maybe an issue?).
    You could also use Microsoft Sentinel as that has a native connector (called:"Microsoft Defender XDR" connector) to move data to another Workspace (even if you dont use Sentinel afterwards). https://learn.microsoft.com/en-us/defender-xdr/microsoft-sentinel-onboard

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful